Skip to content

The Agentic SOC, Delivered: Exabeam Accelerates AI-Powered Security Operations to Machine Speed — Read the News

Model Context Protocol Server: 4 Types and Key Capabilities

  • 8 minutes to read

Table of Contents

    What Is a Model Context Protocol (MCP) Server? 

    Model Context Protocol (MCP) servers are open-source, standardized wrappers that connect AI assistants (like Claude) to external data sources, APIs, and tools. They allow AI models to dynamically discover capabilities and interact securely with files, databases, or web applications without relying on custom, ad-hoc integrations.

    Popular MCP server categories:

    • Developer and code MCP servers: Connect AI assistants to repositories, IDEs, CI/CD pipelines, and developer tools for coding and software engineering workflows.
    • Data and knowledge MCP servers: Expose databases, knowledge bases, document repositories, and enterprise search systems to provide grounded context.
    • IT, cloud, and DevOps MCP servers: Integrate with cloud platforms, monitoring tools, infrastructure, and automation systems to support operational workflows.
    • Security operations MCP servers: Connect AI agents to SIEM, SOAR, EDR, identity, and threat intelligence platforms for security investigations and response.

    Why MCP Servers Matter 

    They Standardize AI Integrations

    MCP servers create a consistent way for AI applications to connect with external systems. Without a standard protocol, every integration between an AI tool and a business application would require custom code, custom authentication patterns, and custom data handling. This becomes difficult to scale as organizations add more models, agents, tools, and data sources.

    With MCP, developers can expose a system once through an MCP server and make it available to multiple compatible AI clients. This reduces integration complexity, improves reuse, and makes it easier to maintain AI connectivity over time. Instead of building one-off connectors, teams can create modular servers for specific systems or domains.

    They Make External Capabilities Discoverable

    MCP servers make external capabilities discoverable by describing the tools, resources, and prompts they provide. This allows an AI client to understand what actions are available, what inputs are required, and what kind of output to expect. For example, a server can declare that it offers a tool for searching security alerts, a resource for reading documentation, or a prompt template for generating an incident report.

    This discoverability matters because AI agents need more than raw access to systems. They need structured descriptions that help them select the right capability for a task. Clear metadata, input schemas, and descriptions reduce ambiguity and help the AI application interact with external systems more reliably.

    They Enable Tool-Using AI Agents

    MCP servers support tool-using AI agents because they expose executable functions that models can call as part of a workflow. Instead of only generating text, an agent can use MCP tools to retrieve live information, analyze external data, update systems, create records, or trigger approved actions.

    This supports enterprise use cases such as security operations, software development, IT support, data analysis, customer support, and workflow automation. The MCP server provides the controlled interface, while the agent decides when a tool or context source is relevant to the user’s request. Done correctly, this enables capable AI systems without giving the model unrestricted access to backend systems.

    Core Capabilities of an MCP Server 

    1. Tools

    Tools are executable functions that an MCP server exposes to an AI client. They allow an AI model or agent to take specific actions, such as querying a database, searching logs, creating a ticket, calling an API, running a calculation, or triggering a workflow. Each tool is typically defined with a name, description, and input schema so the AI client can understand when and how to use it.

    Importance:

    Tools are important when an AI application needs to do more than generate text. They give the model a controlled way to interact with external systems while keeping the execution logic inside the MCP server. This helps organizations expose capabilities to AI agents without giving the model direct, unrestricted access to backend services.

    Related content: Read our guide to agentic AI tools

    2. Resources

    Resources are pieces of readable context that an MCP server makes available to an AI client. These can include files, documents, database records, logs, configuration data, application state, code snippets, or other structured and unstructured information. Unlike tools, resources focus on providing information rather than performing an action.

    Importance:

    Resources help AI applications ground their responses in relevant external context. For example, an MCP server might expose a product manual, a customer record, a security alert, or a repository file so the model can answer questions more accurately. By making resources available through a standard interface, MCP servers reduce the need for custom retrieval logic in each AI application.

    3. Prompts

    Prompts are reusable prompt templates that an MCP server can provide to guide common tasks or workflows. They can define structured instructions for activities such as summarizing an incident, analyzing a document, generating a report, reviewing code, or preparing a support response. Prompts may include variables that the user or client can fill in before the model uses them.

    Importance:

    This capability helps standardize how AI applications handle repeatable tasks. Instead of relying on every user or developer to write prompts from scratch, teams can publish approved prompt templates through the MCP server. This improves consistency, reduces errors, and aligns AI behavior with organizational workflows and policies.

    4. Notifications and State Updates

    Notifications and state updates allow an MCP server to inform the client when something changes. For example, a server may notify the client that available tools have changed, a resource has been updated, a long-running task has progressed, or a connection state has shifted. These updates help the AI client maintain an accurate view of what the server can provide.

    Importance:

    This is useful in environments where tools, resources, permissions, or external system states change over time. Instead of assuming that server capabilities are static, the client can respond to updates and refresh its understanding when needed. This makes MCP-based integrations more reliable for systems that evolve during a session or across deployments.

    Tips from the expert

    Steve Moore

    Steve Moore is Vice President and Chief Security Strategist at Exabeam, helping drive solutions for threat detection and advising customers on security programs and breach response. He is the host of the “The New CISO Podcast,” a Forbes Tech Council member, and Co-founder of TEN18 at Exabeam.

    In my experience, here are tips that can help you better design, deploy, and operate MCP servers in enterprise environments:

    1. Treat the MCP server as a security boundary: Don’t think of the server as a thin API wrapper. It should enforce authentication, authorization, input validation, output filtering, rate limiting, and auditing before any request reaches backend systems.
    2. Separate high-risk capabilities into dedicated servers: Instead of exposing read-only and administrative tools from the same MCP server, create separate servers (for example, “Documentation Server” and “Production Operations Server”). This simplifies access control and reduces blast radius if a server is compromised.
    3. Optimize capability discovery for the model: Servers with dozens of vaguely described tools make tool selection less reliable. Expose only relevant capabilities for each user or role, and write descriptions that clearly explain when each tool should be used.
    4. Minimize context returned to the model: Resist the temptation to return entire documents or large datasets. Return only the information necessary for the current task. Smaller, targeted responses improve model accuracy, reduce token costs, and minimize unnecessary data exposure.
    5. Implement defense against prompt injection in external data: Resources retrieved from web pages, emails, documents, or ticket systems may contain instructions intended to manipulate AI models. The MCP server should sanitize or label untrusted content before passing it to the client.

    Key MCP Server Categories 

    Developer and Code MCP Servers

    Developer and code MCP servers connect AI assistants to software development environments, repositories, build systems, issue trackers, and documentation. They can expose capabilities such as: 

    • Reading code files
    • Searching a repository
    • Analyzing pull requests
    • Checking dependency information
    • Retrieving CI/CD status
    • Creating development tickets

    These servers are useful for coding agents, IDE assistants, and engineering workflows because they give AI systems structured access to the tools developers already use. Instead of working only from copied code snippets, the AI application can interact with relevant project context, understand repository structure, and support tasks such as debugging, code review, documentation, and release preparation.

    Data and Knowledge MCP Servers

    Data and knowledge MCP servers expose structured or unstructured information to AI applications. Their main role is to help AI systems retrieve relevant context and generate more accurate, grounded responses. This can include: 

    • Databases
    • Data warehouses
    • Document repositories
    • Knowledge bases
    • Search indexes
    • Wikis
    • Customer records
    • Product documentation
    • Internal policies

    These servers are commonly used for enterprise search, analytics, reporting, customer support, research, and internal knowledge management. By connecting AI models to trusted information sources through a standardized interface, organizations can reduce hallucinations, improve answer quality, and make internal data easier to use without directly exposing entire backend systems to the model.

    IT, Cloud, and DevOps MCP Servers

    IT, cloud, and DevOps MCP servers connect AI agents to infrastructure, operations tools, cloud platforms, monitoring systems, configuration repositories, and automation workflows. They may provide capabilities such as:

    • Checking service health
    • Querying logs
    • Reviewing deployment status
    • Inspecting cloud resources
    • Opening incidents
    • Triggering approved runbooks

    These servers help AI applications support operational tasks across complex environments. For example, an AI assistant could use an MCP server to investigate why a service is down, summarize recent deployment changes, or help an engineer troubleshoot a cloud resource. In enterprise settings, these servers should include strong access controls and clear limits because they may interact with production systems.

    Security Operations MCP Servers

    Security operations MCP servers expose security-relevant tools, data, and workflows to AI agents. They can connect to systems such as SIEM platforms, SOAR tools, EDR/XDR products, identity systems, vulnerability scanners, threat intelligence feeds, and case management platforms. Typical capabilities include:

    • Searching alerts
    • Retrieving incident details
    • Enriching indicators
    • Checking user activity
    • Summarizing investigations
    • Triggering approved response actions

    These servers are relevant for SOC and threat detection use cases because they give AI agents access to the context needed to triage and investigate security events. A security-focused MCP server can help analysts correlate signals across tools, reduce manual investigation time, and generate incident summaries. Because these workflows may involve sensitive data or response actions, security MCP servers should include strict authorization, audit logging, approval gates, and least-privilege tool design.

    How to Choose or Evaluate an MCP Server 

    Choosing an MCP server is not only about whether it can connect to a specific tool or data source. Organizations should also evaluate how the server handles security, reliability, permissions, scalability, and operational control. The right MCP server should expose capabilities to AI agents while keeping sensitive systems protected and manageable:

    • Available tools and resources: Evaluate what capabilities the MCP server exposes. A strong server should provide clearly defined tools, relevant resources, and useful prompts that match business or technical workflows.
    • Tool descriptions and schemas: Review whether each tool has clear metadata, descriptions, and input schemas. Well-designed schemas help AI clients understand how to use the tool correctly and reduce the risk of invalid or unintended actions.
    • Security and access controls: Check how the server manages authentication, authorization, and permissions. MCP servers should follow least-privilege principles and ensure users or agents can only access the systems and actions they are approved to use.
    • Approval controls for sensitive actions: Look for human-in-the-loop approval options for high-risk operations, such as deleting data, changing configurations, sending messages, modifying tickets, or triggering production workflows.
    • Audit logging and monitoring: The server should log tool calls, inputs, outputs, user context, errors, and administrative changes.
    • Integration quality: Assess how reliably the server connects to the target system. A good MCP server should handle authentication flows, API limits, errors, pagination, and data formatting without requiring manual workarounds.
    • Reliability and error handling: Evaluate how the server behaves when tools fail, external APIs are unavailable, or inputs are incomplete. Clear error messages and predictable failure behavior are important for safe agent workflows.
    • Data protection: Consider what data the server exposes to AI clients and how sensitive information is filtered, redacted, or scoped. The server should avoid sending unnecessary secrets, credentials, personal data, or confidential records into model context.
    • Deployment and maintenance: Review whether the server can be deployed in your preferred environment, such as local, cloud, containerized, or enterprise-managed infrastructure. Also consider update frequency, versioning, documentation, and maintainability.
    • Enterprise governance fit: For larger organizations, the MCP server should fit into governance processes, including approved server registries, policy enforcement, centralized visibility, change management, and lifecycle management.

    Connecting Security Operations Platforms to the Model Context Protocol

    Modern security operations leverage the Model Context Protocol (MCP) to bridge the gap between large language models and security analytics platforms. By standardizing how artificial intelligence assistants interact with security context, organizations can integrate advanced reasoning into their daily workflows without custom code or vendor lock-in.

    Bring Your Own AI in the New-Scale Platform

    The New-Scale Security Operations Platform connects with enterprise AI models, such as Claude, Gemini, or ChatGPT, through a dedicated MCP server. This integration provides a secure gateway for external LLMs to interact with the full security context of New-Scale, including alerts, event logs, and behavioral timelines.

    Capabilities of the New-Scale MCP server:

    • Triage and investigation: External AI assistants query alerts and cases, search event logs using natural language, and retrieve behavioral timelines to assist analysts in real time.
    • Claude Code Skills Pack: Pre-packaged skills provide structured templates that guide models through complex tasks like alert triage, case prioritization, and detection tuning.
    • Rule and parser management: Analysts use natural language prompts to query coverage scores, identify framework gaps, and refine correlation rules.
    • Automated triage: The server supports autonomous workflows that enrich, evaluate, and close low-risk alerts without manual human intervention.

    Community-Driven MCP for LogRhythm SIEM

    LogRhythm SIEM provides a community-driven MCP server that connects local or proprietary LLMs to the local SIEM environment. This open-source wrapper, accessible via GitHub, allows security teams to build custom agentic workflows on top of their existing SIEM deployment.

    Capabilities of the LogRhythm SIEM MCP server:

    • Natural language query: Analysts query event data and investigate alarms using direct conversational prompts.
    • Built-in analyst skills: The server comes with pre-configured templates that help local models interpret logs, triage events, and identify data patterns.
    • Workflow optimization: Administrators use local AI assistants to streamline routine triage and troubleshoot complex detection configurations.
    • Community collaboration: The open-source model allows teams to share skills, tools, and custom integrations across the broader security community.

    To learn more visit the MCP for developers page.

    Learn More About Exabeam

    Learn about the Exabeam platform and expand your knowledge of information security with our collection of white papers, podcasts, webinars, and more.

    • Data Sheet

      New-Scale Fusion

    • Blog

      What’s New in Exabeam New-Scale for October 2026

    • Report

      Gartner® Emerging Tech: AI Vendor Race

    • Blog

      The Agentic SOC Isn’t Coming for Analysts’ Jobs. It’s Coming for Their Tabs.

    • Show More